Available for day contractsFrom 21st September I have availability for day and half day contracts. Please contact for more information.

Contact →
mikepreston.org

tcpdump/Wireshark

Command-line and GUI tools for network packet capture and protocol analysis.

tcpdump/Wireshark

Command-line and GUI tools for network packet capture and protocol analysis.

Overview

tcpdump is a command-line packet analyser that captures and displays network traffic in real-time. Wireshark provides a graphical interface with advanced protocol dissection capabilities. Both tools use the libpcap/WinPcap libraries for packet capture and share similar capture filter syntax (BPF - Berkeley Packet Filter), though Wireshark uses its own display filter syntax.

These tools are essential for network troubleshooting, security analysis, protocol development, and understanding network behaviour.

Network InterfaceCapture FilterBPF SyntaxPacket Capturetcpdump/WiresharkDisplay FilterWireshark onlyProtocol AnalysisSave to PCAPNetwork InterfaceCapture FilterBPF SyntaxPacket Capturetcpdump/WiresharkDisplay FilterWireshark onlyProtocol AnalysisSave to PCAP

Capture Filter Syntax

Capture filters determine which packets are captured from the network interface. They use Berkeley Packet Filter (BPF) syntax and are applied before packet capture, reducing CPU and storage overhead.

Key Concepts

BPF primitives:

  • host - Match IP address or hostname
  • net - Match network CIDR
  • port - Match port number
  • src/dst - Specify source or destination
  • tcp/udp/icmp - Match protocol
  • portrange - Match port range

Logical operators:

  • and (or &&) - Both conditions must be true
  • or (or ||) - Either condition must be true
  • not (or !) - Negation

Protocol qualifiers:

  • ether - Ethernet layer
  • ip/ip6 - IP layer
  • tcp/udp - Transport layer

Common Capture Filters

# Capture traffic for specific host
host 192.168.1.100

# Capture traffic to/from specific network
net 192.168.1.0/24

# Capture specific port
port 80

# Capture port range
portrange 8000-9000

# Source and destination
src host 192.168.1.100
dst port 443

# Protocol-specific
tcp port 22
udp port 53

# Multiple conditions with AND
host 192.168.1.100 and port 80

# Multiple conditions with OR
port 80 or port 443

# Exclude traffic (NOT)
not port 22
not host 192.168.1.1

# Complex filters
tcp port 80 and src net 192.168.0.0/16

# HTTP/HTTPS traffic
port 80 or port 443 or port 8080

# DNS queries
udp port 53

# Exclude broadcast and multicast
not broadcast and not multicast

# Capture only SYN packets (TCP flags)
tcp[tcpflags] & tcp-syn != 0 and tcp[tcpflags] & tcp-ack == 0

# Packets larger than N bytes
greater 1000
less 100

Examples

# Capture HTTP traffic from specific host
tcpdump -i eth0 'host 192.168.1.50 and tcp port 80'

# Capture all traffic except SSH
tcpdump -i any 'not port 22'

# Capture traffic between two hosts
tcpdump -i eth0 'host 192.168.1.10 and host 192.168.1.20'

# Capture all traffic to external networks (not RFC1918)
tcpdump -i eth0 'not net 10.0.0.0/8 and not net 172.16.0.0/12 and not net 192.168.0.0/16'

Common Capture Patterns

Pre-configured filters for typical network analysis scenarios.

By Host

# All traffic for specific host
tcpdump host 192.168.1.100

# Traffic from host
tcpdump src host 192.168.1.100

# Traffic to host
tcpdump dst host 192.168.1.100

# Traffic between two hosts
tcpdump host 192.168.1.10 and host 192.168.1.20

# Multiple hosts
tcpdump 'host 192.168.1.10 or host 192.168.1.20 or host 192.168.1.30'

By Port

# Web traffic
tcpdump 'port 80 or port 443'

# SSH traffic
tcpdump port 22

# Mail protocols
tcpdump 'port 25 or port 587 or port 143 or port 993'

# Database traffic
tcpdump 'port 3306 or port 5432 or port 27017'

# Port range
tcpdump portrange 8000-9000

By Protocol

# TCP traffic only
tcpdump tcp

# UDP traffic only
tcpdump udp

# ICMP (ping) traffic
tcpdump icmp

# IPv6 traffic
tcpdump ip6

# ARP traffic
tcpdump arp

# Specific IP protocol number
tcpdump 'ip proto 50'  # ESP (IPsec)

Advanced Patterns

# HTTP GET requests
tcpdump -i eth0 -s 0 -A 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420)'

# HTTP POST requests
tcpdump -i eth0 -s 0 -A 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x504F5354)'

# TCP SYN packets (connection attempts)
tcpdump 'tcp[tcpflags] & tcp-syn != 0'

# TCP RST packets
tcpdump 'tcp[tcpflags] & tcp-rst != 0'

# Fragmented IP packets
tcpdump 'ip[6:2] & 0x3fff != 0'

# IPv4 with TTL less than 5
tcpdump 'ip[8] < 5'

# Broadcast traffic
tcpdump broadcast

# Multicast traffic
tcpdump multicast

tcpdump Command Options

Essential command-line flags for packet capture and output formatting.

Basic Options

# List available interfaces
tcpdump -D

# Capture on specific interface
tcpdump -i eth0
tcpdump -i any  # All interfaces

# Limit number of packets
tcpdump -c 100

# Read from capture file
tcpdump -r capture.pcap

# Write to capture file
tcpdump -w output.pcap

# Rotate to a new file every 10 MB (-C is size-based rotation, not append:
# files become output.pcap, output.pcap1, output.pcap2, …)
tcpdump -w output.pcap -C 10

Output Format Options

# Verbose output (more detail)
tcpdump -v
tcpdump -vv   # More verbose
tcpdump -vvv  # Even more verbose

# Print packets in ASCII
tcpdump -A

# Print packets in HEX and ASCII
tcpdump -X

# Don't resolve hostnames
tcpdump -n

# Don't resolve hostnames or ports
tcpdump -nn

# Show absolute sequence numbers
tcpdump -S

# Capture full packet (not just headers)
tcpdump -s 0      # Modern tcpdump
tcpdump -s 65535  # Older versions

# Timestamp format
tcpdump -t        # No timestamp
tcpdump -tt       # Unix epoch
tcpdump -ttt      # Delta from previous packet
tcpdump -tttt     # Human-readable with date

Practical Examples

# Capture HTTP traffic with full packets and ASCII output
tcpdump -i eth0 -s 0 -A 'tcp port 80'

# Capture to file without hostname resolution
tcpdump -i any -nn -w capture.pcap

# Verbose capture of DNS traffic
tcpdump -i eth0 -vvv -s 0 udp port 53

# Capture with timestamps and packet count
tcpdump -i eth0 -tttt -c 1000 host 192.168.1.100

# Rotate capture files (100MB each, max 5 files)
tcpdump -i eth0 -w capture.pcap -C 100 -W 5

# Read and filter existing capture
tcpdump -r input.pcap -nn 'port 443' -w filtered.pcap

# Quick traffic monitoring
tcpdump -i eth0 -nn -q  # Quiet mode

Display Filters (Wireshark)

Display filters in Wireshark control which captured packets are shown. Unlike capture filters, they don't affect what's captured and can be changed dynamically.

Key Concepts

Display filters use a different syntax from capture filters:

  • Field-based: protocol.field operator value
  • Comparisons: ==, !=, >, <, >=, <=
  • Logical: and, or, not, xor
  • Membership: in, contains, matches (regex)
MatchNo MatchCaptured PacketsDisplay FilterShow PacketHide PacketPacket ListMatchNo MatchCaptured PacketsDisplay FilterShow PacketHide PacketPacket List

Common Display Filters

# IP address
ip.addr == 192.168.1.100
ip.src == 192.168.1.100
ip.dst == 192.168.1.100

# Network range
ip.addr == 192.168.1.0/24

# Port
tcp.port == 80
tcp.srcport == 443
tcp.dstport == 8080

# Protocol
http
dns
ssh
tls
icmp

# HTTP methods
http.request.method == "GET"
http.request.method == "POST"

# HTTP status codes
http.response.code == 200
http.response.code >= 400

# HTTP URIs
http.request.uri contains "api"
http.host == "example.com"

# DNS queries
dns.qry.name == "example.com"
dns.flags.response == 0  # Queries only
dns.flags.response == 1  # Responses only

# TCP flags
tcp.flags.syn == 1
tcp.flags.ack == 1
tcp.flags.rst == 1
tcp.flags.fin == 1

# TCP streams
tcp.stream == 5

# Packet length
frame.len > 1000
frame.len < 100

# Time-based
frame.time >= "2024-01-01 00:00:00"
frame.time_delta > 1  # More than 1 second since previous packet

# TLS/SSL
tls.handshake.type == 1  # Client Hello
tls.handshake.type == 2  # Server Hello
ssl.record.content_type == 23  # Application Data

# Multiple conditions
ip.addr == 192.168.1.100 and tcp.port == 80
http or dns
not arp and not icmp

Advanced Display Filters

# Follow TCP conversations
tcp.stream eq 42

# Retransmissions
tcp.analysis.retransmission

# Duplicate ACKs
tcp.analysis.duplicate_ack

# Zero window (receiver buffer full)
tcp.analysis.zero_window

# Connection resets
tcp.flags.reset == 1

# HTTP with specific user agent
http.user_agent contains "curl"

# Contains specific string in payload
frame contains "password"
tcp contains "admin"

# Regular expression matching (escape the backslash inside the quoted string)
http.host matches ".*\\.example\\.com"

# Malformed packets
_ws.malformed

# Expert info (warnings/errors)
_ws.expert.severity == error
_ws.expert.severity == warning

# Packets with specific TTL
ip.ttl < 10

# Fragmented packets
ip.flags.mf == 1  # More fragments flag

# Large packets
tcp.len > 1400

# Specific MAC address
eth.addr == 00:11:22:33:44:55

# VLAN tagged
vlan

# IPv6
ipv6.addr == 2001:db8::1

Filter Expressions

# Bookmarked for quick access
# Save frequently used filters as buttons in Wireshark

# Web browsing traffic
(http or tls) and not (ssdp or mdns)

# Database traffic
tcp.port in {3306, 5432, 1433, 27017}

# Email protocols
tcp.port in {25, 587, 465, 110, 995, 143, 993}

# VoIP traffic
rtp or sip or rtcp

# Network management
snmp or icmp

# File sharing
smb or smb2 or nfs

# Remote access
ssh or rdp or vnc

Protocol Analysis

Understanding and dissecting specific network protocols.

HTTP/HTTPS Analysis

# Wireshark display filters
http
http.request
http.response

# HTTP methods
http.request.method == "GET"
http.request.method == "POST"
http.request.method == "PUT"
http.request.method == "DELETE"

# Status codes
http.response.code == 200  # OK
http.response.code == 404  # Not Found
http.response.code >= 500  # Server errors

# Headers
http.header.name == "Content-Type"
http.cookie contains "session"

# Export HTTP objects
# File → Export Objects → HTTP

# Follow HTTP stream
# Right-click packet → Follow → HTTP Stream

DNS Analysis

# All DNS traffic
dns

# Queries only
dns.flags.response == 0

# Responses only
dns.flags.response == 1

# Specific query type
dns.qry.type == 1   # A record
dns.qry.type == 28  # AAAA record
dns.qry.type == 15  # MX record
dns.qry.type == 16  # TXT record

# Query name
dns.qry.name == "example.com"
dns.qry.name contains "google"

# Response codes
dns.flags.rcode == 0  # No error
dns.flags.rcode == 3  # NXDOMAIN

# DNS over TLS (DoT runs on port 853)
tls && tcp.port == 853

TCP Connection Analysis

ServerClientServerClientThree-Way HandshakeData TransferConnection TerminationSYNSYN-ACKACKData + ACKACKData + ACKACKFINACKFINACKServerClientServerClientThree-Way HandshakeData TransferConnection TerminationSYNSYN-ACKACKData + ACKACKData + ACKACKFINACKFINACK
# Connection establishment (SYN)
tcp.flags.syn == 1 and tcp.flags.ack == 0

# Connection response (SYN-ACK)
tcp.flags.syn == 1 and tcp.flags.ack == 1

# Connection termination (FIN)
tcp.flags.fin == 1

# Connection reset (RST)
tcp.flags.reset == 1

# Follow TCP stream
# Right-click → Follow → TCP Stream

# TCP stream number
tcp.stream == 0

# TCP analysis flags
tcp.analysis.flags
tcp.analysis.retransmission
tcp.analysis.duplicate_ack
tcp.analysis.lost_segment
tcp.analysis.out_of_order
tcp.analysis.window_full
tcp.analysis.zero_window

# Window size issues
tcp.window_size_value == 0
tcp.window_size_value < 8192

TLS/SSL Analysis

# All TLS traffic
tls

# Handshake messages
tls.handshake.type == 1   # Client Hello
tls.handshake.type == 2   # Server Hello
tls.handshake.type == 11  # Certificate
tls.handshake.type == 16  # Client Key Exchange

# TLS versions (record-layer version field)
tls.record.version == 0x0301  # TLS 1.0
tls.record.version == 0x0302  # TLS 1.1
tls.record.version == 0x0303  # TLS 1.2
tls.record.version == 0x0304  # TLS 1.3
# Caveat: TLS 1.3 pins the record-layer version to 0x0303 on the wire for
# compatibility (the real version is in the supported_versions extension), so
# matching 1.3 by record.version rarely works — filter on tls.handshake.extensions
# or the negotiated tls.handshake.version instead.

# Server Name Indication (SNI)
tls.handshake.extensions_server_name

# Certificate details
x509sat.printableString
x509ce.dNSName

# Alert messages
tls.alert_message

# Decrypt TLS (if you have private key)
# Edit → Preferences → Protocols → TLS → RSA keys list

ICMP Analysis

# All ICMP traffic
icmp

# Ping request
icmp.type == 8

# Ping reply
icmp.type == 0

# Destination unreachable
icmp.type == 3

# Time exceeded (traceroute)
icmp.type == 11

# ICMPv6
icmpv6

Saving and Reading Captures

Managing packet capture files for storage, sharing, and analysis.

Capture File Formats

PCAP (.pcap) - Standard format, widely supported PCAPNG (.pcapng) - Next generation, supports metadata, multiple interfaces

tcpdump File Operations

# Save capture to file
tcpdump -w capture.pcap

# Save with full packet capture
tcpdump -s 0 -w capture.pcap

# Capture with file rotation
tcpdump -w capture.pcap -C 100  # New file every 100MB
tcpdump -w capture.pcap -C 100 -W 10  # Keep max 10 files

# Capture for specific duration
timeout 60 tcpdump -w capture.pcap  # 60 seconds

# Read from file
tcpdump -r capture.pcap

# Read and apply filter
tcpdump -r input.pcap 'port 80' -w filtered.pcap

# Read with verbose output
tcpdump -r capture.pcap -vvv -nn

# Display specific packet count from file
tcpdump -r capture.pcap -c 100

# Print packet timestamps
tcpdump -r capture.pcap -tttt

# Combine multiple capture files
mergecap -w combined.pcap file1.pcap file2.pcap file3.pcap

# Split capture file by time
editcap -i 60 input.pcap output.pcap  # Split every 60 seconds

# Split capture file by packet count
editcap -c 1000 input.pcap output.pcap  # 1000 packets per file

# Remove duplicate packets
editcap -d input.pcap output.pcap

# Extract specific time range
editcap -A "2024-01-01 10:00:00" -B "2024-01-01 11:00:00" input.pcap output.pcap

Wireshark File Operations

# Save entire capture
# File → Save As

# Save filtered packets
# Apply display filter → File → Export Specified Packets

# Save specific packet range
# File → Export Specified Packets → Range

# Export objects (HTTP, SMB, etc.)
# File → Export Objects → [Protocol]

# Merge capture files
# File → Merge

# Import from hex dump
# File → Import from Hex Dump

# Capture file properties
# Statistics → Capture File Properties

tshark (Wireshark CLI)

# Basic capture
tshark -i eth0 -w capture.pcap

# Capture with display filter (after capture)
tshark -i eth0 -Y 'http' -w http.pcap

# Capture with capture filter (before capture)
tshark -i eth0 -f 'port 80' -w capture.pcap

# Read and display
tshark -r capture.pcap

# Read with display filter
tshark -r capture.pcap -Y 'ip.addr == 192.168.1.100'

# Extract specific fields
tshark -r capture.pcap -T fields -e ip.src -e ip.dst -e tcp.port

# JSON output
tshark -r capture.pcap -T json

# Statistics
tshark -r capture.pcap -q -z io,stat,1  # I/O statistics per second
tshark -r capture.pcap -q -z conv,tcp   # TCP conversations

# Protocol hierarchy
tshark -r capture.pcap -q -z io,phs

# Extract HTTP URIs
tshark -r capture.pcap -Y http.request -T fields -e http.host -e http.request.uri

# Count packets by protocol
tshark -r capture.pcap -q -z io,phs

Troubleshooting Network Issues

Common network problems and how to diagnose them using tcpdump/Wireshark.

Connection Issues

NoYesNoYesNoYesNoYesConnection ProblemCan you see SYN?Checkrouting/firewallSee SYN-ACK?Server notrespondingCheckfirewall/serviceSee ACK?Client issueCheck clientfirewallSee data transfer?Application layerissueConnectionestablishedCheck latency/errorsNoYesNoYesNoYesNoYesConnection ProblemCan you see SYN?Checkrouting/firewallSee SYN-ACK?Server notrespondingCheckfirewall/serviceSee ACK?Client issueCheck clientfirewallSee data transfer?Application layerissueConnectionestablishedCheck latency/errors

Symptoms: Cannot connect to service

# tcpdump - capture connection attempts
tcpdump -i any -nn 'host TARGET_IP and port TARGET_PORT'

# Wireshark display filters
tcp.flags.syn == 1 and tcp.flags.ack == 0  # SYN packets
tcp.flags.reset == 1                        # RST packets

# Check for:
# 1. SYN sent but no SYN-ACK → Firewall or routing issue
# 2. SYN-ACK sent but no ACK → Client-side firewall
# 3. RST received → Service refused connection
# 4. No response at all → Network unreachable

Performance Issues

Symptoms: Slow application performance, timeouts

# Check for retransmissions (tcpdump)
tcpdump -i any -nn 'tcp[tcpflags] & tcp-push != 0'

# Wireshark display filters
tcp.analysis.retransmission              # Retransmitted packets
tcp.analysis.duplicate_ack               # Duplicate ACKs
tcp.analysis.lost_segment                # Lost segments
tcp.analysis.window_full                 # Window full
tcp.analysis.zero_window                 # Zero window
frame.time_delta > 1                     # Large delays between packets

# Statistics in Wireshark
# Statistics → TCP Stream Graphs → Time Sequence (Stevens)
# Statistics → TCP Stream Graphs → Round Trip Time
# Statistics → I/O Graph

# Check for:
# 1. High retransmission rate → Packet loss
# 2. Zero window → Receiver can't keep up
# 3. Duplicate ACKs → Packet loss or reordering
# 4. Large RTT → Network latency

DNS Issues

Symptoms: Name resolution failures, slow resolution

# Capture DNS traffic
tcpdump -i any -nn 'udp port 53'

# Wireshark display filters
dns.flags.rcode != 0                     # DNS errors
dns.flags.rcode == 3                     # NXDOMAIN
dns.qry.name == "example.com"            # Specific query
frame.time_delta > 1 and dns             # Slow responses

# Check for:
# 1. NXDOMAIN responses → Domain doesn't exist
# 2. No response → DNS server unreachable
# 3. Slow responses → DNS server performance issue
# 4. SERVFAIL → DNS server configuration issue

HTTP/Application Issues

Symptoms: HTTP errors, application failures

# Capture HTTP traffic
tcpdump -i any -s 0 -A 'tcp port 80 or tcp port 443'

# Wireshark display filters
http.response.code >= 400                # Client errors
http.response.code >= 500                # Server errors
http.request.method == "POST"            # POST requests
http.response.code == 0                  # No response

# Follow HTTP stream
# Right-click packet → Follow → HTTP Stream

# Export HTTP objects
# File → Export Objects → HTTP

# Check for:
# 1. 4xx errors → Client-side issues
# 2. 5xx errors → Server-side issues
# 3. Connection reset during transfer → Network or server issue
# 4. Large response times → Server performance issue

Packet Loss Detection

# Check TCP sequence numbers for gaps
tcp.analysis.lost_segment

# Check for out-of-order packets
tcp.analysis.out_of_order

# I/O graph showing packet loss patterns
# Statistics → I/O Graph
# Add filter: tcp.analysis.retransmission

# Calculate packet loss percentage
# Statistics → Capture File Properties

Latency Analysis

# Time-based filters
frame.time_delta > 0.1                   # Gaps > 100ms
tcp.time_delta > 0.1                     # TCP response delay

# TCP RTT
tcp.analysis.ack_rtt > 0.1              # ACK RTT > 100ms

# Statistics
# Statistics → TCP Stream Graphs → Round Trip Time
# Statistics → I/O Graph with AVG/MIN/MAX filters

# Identify latency sources:
# 1. Network propagation delay
# 2. Server processing time
# 3. Congestion/queuing delay

SSL/TLS Troubleshooting

# Capture TLS handshake
tcpdump -i any -s 0 -nn 'tcp port 443'

# Wireshark display filters
tls.alert_message                        # TLS alerts
tls.handshake.type == 1                  # Client Hello
tls.handshake.type == 2                  # Server Hello

# Check for:
# 1. Alert messages → Certificate or cipher issues
# 2. Handshake failures → Version or cipher mismatch
# 3. Certificate validation errors
# 4. Incomplete handshakes → Firewall dropping packets

Broadcast/Multicast Storm

# Capture broadcast traffic
tcpdump -i any broadcast

# Capture multicast traffic
tcpdump -i any multicast

# Wireshark display filters
eth.dst == ff:ff:ff:ff:ff:ff             # Broadcast
ip.dst >= 224.0.0.0                      # Multicast

# Statistics
# Statistics → Protocol Hierarchy
# Statistics → Conversations
# Statistics → I/O Graph

# Identify source of excessive broadcast/multicast traffic

Quick Reference

tcpdump Essential Commands

Command Description
tcpdump -i eth0 Capture on eth0
tcpdump -i any Capture on all interfaces
tcpdump -nn No hostname/port resolution
tcpdump -w file.pcap Save to file
tcpdump -r file.pcap Read from file
tcpdump -c 100 Capture 100 packets
tcpdump -s 0 Capture full packets
tcpdump -A ASCII output
tcpdump -X Hex and ASCII output
tcpdump -vvv Maximum verbosity

Common Capture Filters (BPF)

Filter Description
host 192.168.1.1 Traffic to/from host
net 192.168.0.0/24 Traffic to/from network
port 80 Traffic on port 80
src host 192.168.1.1 From specific host
dst port 443 To specific port
tcp TCP traffic only
udp UDP traffic only
icmp ICMP traffic only
not port 22 Exclude SSH
portrange 8000-9000 Port range

Common Display Filters (Wireshark)

Filter Description
ip.addr == 192.168.1.1 IP address
tcp.port == 80 TCP port
http HTTP traffic
dns DNS traffic
tls TLS/SSL traffic
http.request.method == "GET" HTTP GET requests
http.response.code == 200 HTTP 200 responses
tcp.flags.syn == 1 TCP SYN packets
tcp.analysis.retransmission Retransmissions
frame.time_delta > 1 Delays > 1 second

Protocol Analysis Shortcuts

Task Tool/Method
Follow TCP conversation Right-click → Follow → TCP Stream
Follow HTTP stream Right-click → Follow → HTTP Stream
Export HTTP objects File → Export Objects → HTTP
View TCP graphs Statistics → TCP Stream Graphs
View protocol hierarchy Statistics → Protocol Hierarchy
View conversations Statistics → Conversations
View endpoints Statistics → Endpoints
I/O statistics Statistics → I/O Graph
Expert information Analyse → Expert Information

File Operations

Task Command
Merge captures mergecap -w out.pcap in1.pcap in2.pcap
Split by time editcap -i 60 in.pcap out.pcap
Split by count editcap -c 1000 in.pcap out.pcap
Remove duplicates editcap -d in.pcap out.pcap
Extract time range editcap -A "start" -B "end" in.pcap out.pcap
Convert format editcap -F pcap in.pcapng out.pcap

tshark Quick Commands

Command Description
tshark -i eth0 -w file.pcap Capture to file
tshark -r file.pcap Read from file
tshark -Y 'http' Display filter
tshark -T fields -e ip.src Extract field
tshark -T json JSON output
tshark -q -z io,stat,1 I/O statistics
tshark -q -z conv,tcp TCP conversations

Common Issues and Solutions

Issue Cause Solution
Permission denied Requires root/admin Run with sudo or as administrator
Interface not found Wrong interface name List interfaces: tcpdump -D or ip link
Capture filter not working Wrong BPF syntax Check syntax, use man pcap-filter
Display filter not working Wrong Wireshark syntax Use auto-complete, check protocol fields
No packets captured Wrong interface or filter too restrictive Use -i any, verify filter
Truncated packets Snaplen too small Use -s 0 for full packets
Can't read PCAP file Permissions or format Check file permissions, verify format
High CPU usage Too much traffic without filter Apply capture filter to reduce load
Large capture files No file rotation Use -C and -W for rotation
Missing packets Dropped by kernel Check tcpdump -vvv for drop stats, increase buffer
Can't decrypt TLS No private key Add private key in Wireshark TLS settings
Hostname resolution slow DNS lookups Use -nn to disable resolution
Wireshark crashes Corrupted file or bug Update Wireshark, try editcap to fix file
Can't see local traffic Loopback not captured Capture on lo interface (Linux) or loopback
Packet order wrong Multiple interfaces Packets timestamped at different points
Export objects fails Incomplete transfer Check for TCP retransmissions/errors